Threat group.View on attack.mitre.org
EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.
| Technique | Procedure example |
|---|---|
| T1102 Web Service |
EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads. |
| T1203 Exploitation for Client Execution |
EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML. |
| T1204.001 Malicious Link |
EXOTIC LILY has used malicious links to lure users into executing malicious payloads. |
| T1204.002 Malicious File |
EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO. |
| T1566.001 Spearphishing Attachment |
EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments. |
| T1566.002 Spearphishing Link |
EXOTIC LILY has relied on victims to open malicious links in e-mails for execution. |
| T1566.003 Spearphishing via Service |
EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing. |
| T1583.001 Domains |
EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”. |
| T1585.001 Social Media Accounts |
EXOTIC LILY has established social media profiles to mimic employees of targeted companies. |
| T1585.002 Email Accounts |
EXOTIC LILY has created e-mail accounts to spoof targeted organizations. |
| T1589.002 Email Addresses |
EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms. |
| T1593.001 Social Media |
EXOTIC LILY has copied data from social media sites to impersonate targeted individuals. |
| T1594 Search Victim-Owned Websites |
EXOTIC LILY has used contact forms on victim websites to generate phishing e-mails. |
| T1597 Search Closed Sources |
EXOTIC LILY has searched for information on targeted individuals on business databases including RocketReach and CrunchBase. |
| T1608.001 Upload Malware |
EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.